VendorsCiscoemail_security_applianceany version
Vulnerabilities

Cisco Email Security Appliance any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2022-20798
Cisco Email Security Appliance and Cisco Secure Email and Web Manager External Authentication Bypass Vulnerability
Published 2022-06-15 · Modified
9.8EPSS 0.015
CVE-2018-15460
Cisco Email Security Appliance URL Filtering Denial of Service Vulnerability
Published 2019-01-10 · Modified
8.6EPSS 0.025
CVE-2022-20664
Cisco Email Security Appliance and Cisco Secure Email and Web Manager Information Disclosure Vulnerability
Published 2022-06-15 · Modified
7.7EPSS 0.010
CVE-2018-0419
A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected system. The vulnerability is due to the improper detection of content within executable (EXE) files. An attacker could exploit this vulnerability by sending a customized EXE file that is not recognized and blocked by the ESA. A successful exploit could allow an attacker to send email messages that contain malicious executable files to unsuspecting users. Cisco Bug IDs: CSCvh03786.
Published 2018-08-15 · Modified
7.5EPSS 0.028
CVE-2016-1461
Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932.
Published 2016-08-01 · Modified
7.5EPSS 0.024
CVE-2020-3133
Cisco Email Security Appliance Content Filter Bypass Vulnerability
Published 2020-09-23 · Modified
7.5EPSS 0.014
CVE-2020-3548
Cisco Email Security Appliance Denial Of Service Vulnerability
Published 2024-11-18 · Analyzed
7.5EPSS 0.008
CVE-2022-20960
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain TLS connections that are processed by an affected device. An attacker could exploit this vulnerability by establishing a large number of concurrent TLS connections to an affected device. A successful exploit could allow the attacker to cause the device to drop new TLS email messages that come from the associated email servers. Exploitation of this vulnerability does not cause the affected device to unexpectedly reload. The device will recover autonomously within a few hours of when the attack is halted or mitigated.
Published 2022-11-03 · Modified
7.5EPSS 0.008
CVE-2021-1566
Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerability
Published 2021-06-16 · Modified
7.4EPSS 0.007
CVE-2023-20009
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a [[privilege of operator - validate actual name]]. The vulnerability is due to the processing of a specially crafted SNMP configuration file. An attacker could exploit this vulnerability by authenticating to the targeted device and uploading a specially crafted SNMP configuration file that when uploaded could allow for the execution of commands as root. An exploit could allow the attacker to gain root access on the device.
Published 2023-02-16 · Modified
7.2EPSS 0.013
CVE-2020-3132
Cisco Email Security Appliance Shortened URL Denial of Service Vulnerability
Published 2020-02-19 · Modified
7.1EPSS 0.015
CVE-2023-20075
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the attacker to escape the restricted command prompt and execute arbitrary commands on the underlying operating system. To successfully exploit this vulnerability, an attacker would need valid Administrator credentials.
Published 2023-02-16 · Modified
6.7EPSS 0.005
CVE-2020-3181
Cisco Email Security Appliance Uncontrolled Resource Exhaustion Vulnerability
Published 2020-03-04 · Modified
6.5EPSS 0.016
CVE-2020-3134
Cisco Email Security Appliance Zip Decompression Engine Denial of Service Vulnerability
Published 2020-01-26 · Modified
6.5EPSS 0.011
CVE-2021-1516
Cisco Content Security Management Appliance, Email Security Appliance, and Web Security Appliance Information Disclosure Vulnerability
Published 2021-05-06 · Modified
6.5EPSS 0.010
CVE-2020-3547
Cisco Email Security Appliance, Cisco Content Security Management Appliance, and Cisco Web Security Appliance Information Disclosure Vulnerability
Published 2020-09-04 · Modified
6.5EPSS 0.009
CVE-2020-3447
Cisco Email Security Appliance and Cisco Content Security Management Appliance Information Disclosure Vulnerability
Published 2020-08-17 · Modified
6.5EPSS 0.007
CVE-2020-3137
Cisco Email Security Appliance Cross-Site Scripting Vulnerability
Published 2020-09-23 · Modified
6.1EPSS 0.008
CVE-2020-3368
Cisco Email Security Appliance URL Filtering Bypass Vulnerability
Published 2020-06-18 · Modified
5.8EPSS 0.014
CVE-2020-3370
Cisco Content Security Management Appliance Filter Bypass Vulnerability
Published 2020-07-16 · Modified
5.8EPSS 0.013
CVE-2018-0447
Cisco Email Security Appliance URL Filtering Bypass Vulnerability
Published 2018-10-05 · Modified
5.3EPSS 0.023
CVE-2022-20675
Multiple Cisco Security Products Simple Network Management Protocol Service Denial of Service Vulnerability
Published 2022-04-06 · Modified
5.3EPSS 0.013
CVE-2020-3164
Cisco ESA, Cisco WSA, and Cisco SMA GUI Denial of Service Vulnerability
Published 2020-03-04 · Modified
5.3EPSS 0.013
CVE-2020-3546
Cisco Email Security Appliance Information Disclosure Vulnerability
Published 2020-09-04 · Modified
5.3EPSS 0.011
CVE-2022-20772
A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by injecting malicious HTTP headers, controlling the response body, or splitting the response into multiple responses.
Published 2022-11-03 · Modified
5.3EPSS 0.006